Iran’s Banks Are Changing Domains After Their SSL Certificates Stopped Validating
With browsers flagging Iranian bank sites as unsafe, some banks moved addresses without warning customers
Iranian banks are moving their websites to new addresses because browsers have stopped trusting the security certificates on the old ones. Bank Melli Iran, the country’s largest state-owned bank, sent customers a text message pointing them to its new domain. Bank Mellat, one of the country's largest commercial banks, switched without announcing the change and left no redirect from the address customers had been using.
The trigger is the certificate itself. An SSL/TLS certificate is what lets a browser confirm that the site in the address bar is the site it claims to be, and Iranian institutions have been losing theirs.
That makes this more than a maintenance problem. A bank is the one place on the web where the browser’s identity check does the most work, and the workaround the sector has settled on-new domains, plus a warning screen users are expected to click past-degrades exactly that check. It is also a live demonstration of something the rest of the web rarely has to think about: the certificate authority system is a shared global utility with a small number of political chokepoints, and Iran is finding out what happens when access to it narrows.
The certificates stopped renewing
A certificate has to chain back to an authority the browser already trusts. If it expires, is revoked, or cannot be traced through that chain, the browser blocks the page and shows a security warning instead.
Iranian sites depend heavily on foreign issuers for those certificates. According to W3Techs, a survey that tracks certificate authority market share, Let’s Encrypt accounts for a very large share of the certificates used on Iranian websites, with Certum, a Polish certificate authority, the other issuer in wide use.
Iranian technologists attribute the revocations to sanctions compliance by those authorities. Neither Let’s Encrypt nor Certum has published a statement specific to Iranian banks, and no affected bank has publicly explained why its certificate stopped working. What the dependency does show is that picking a non-American issuer does not by itself make the trust chain independent.
Not only the banks
The errors have not been confined to lenders. Domains belonging to the Central Bank of Iran, which sets the official exchange rate and licenses the country’s payment providers, and to the Communications Regulatory Authority, the telecom ministry’s licensing arm, have shown the same warning at points, as have some other government sites.
A new domain is its own attack surface
Changing address does sidestep the certificate problem on the old domain. It also creates a new one.
Old links, search results, mobile apps and saved bookmarks still point at the retired address. A customer who cannot reach their bank goes looking for it-on a search engine, or on social media-and that is precisely the environment in which an official banking domain and a convincing imitation are hardest to tell apart. The banks that moved without notice or a redirect have pushed the largest number of customers into that search.

The warning that stops meaning anything
The browser warning exists to stop people entering sensitive information on a site whose identity cannot be confirmed. It works because it is rare.
When it appears repeatedly on legitimate bank and government sites, and users have to dismiss it to do routine business, it stops functioning as a signal and becomes a step in the process. The habit is not domain-specific. A customer trained to click through “your connection is not private” on their own bank’s site will click through it on a phishing page built to look like that bank.
How many Iranian domains have lost certificates is not established, and no authority or institution has put a number on it.